• Our Minecraft servers are offline but we will keep this forum online for any community communication. Site permissions for posting could change at a later date but will remain online.

The ShellShock Virus.

bridgedragon

Diamond
Joined
Nov 24, 2013
Messages
455
Reaction score
269
So I'm sitting here on the couch, browsing the forums on my tablet. Then on the news I see "The Shellshock virus could leave millions of electronic devices vulnerable to cyberattacks." So I'm like o,o and yeah. Now that I think about it, idk why I made this thread. But I need a computer wizard to like, write 8 paragraphs on like pre-cautions yaddaadadada mmk.
On a serious note, this virus is apparently EXTREMELY BAD. Like more bad then the heartbleed bug.
 

IronOre12

Platinum
Joined
Apr 28, 2014
Messages
571
Reaction score
609
The potential is enormous – “getting shell” on a box has always been a major win for an attacker because of the control it offers them over the target environment. Access to internal data, reconfiguration of environments, publication of their own malicious code etc. It’s almost limitless and it’s also readily automatable. There are many, many examples of exploits out there already that could easily be fired off against a large volume of machines.

Unfortunately when it comes to arbitrary code execution in a shell on up to half the websites on the internet, the potential is pretty broad. One of the obvious (and particularly nasty) ones is dumping internal files for public retrieval. Password files and configuration files with credentials are the obvious ones, but could conceivably extend to any other files on the system.

Likewise, the same approach could be applied to write files to the system. This is potentially the easiest website defacement vector we’ve ever seen, not to mention a very easy way of distributing malware

Source: Troyhunt.com
 

Ceroria

Mockingjay
Joined
Aug 20, 2012
Messages
11,024
Reaction score
13,943
... and now I'm scared becuase I just got a new computer at my dad's house and went through the whole process of installing a security system listening to all their scary stories about how if you didn't get their software, things like this very virus will get you...

*shivers*
 

Mooclan

Forum God
Joined
Aug 19, 2012
Messages
6,358
Reaction score
12,666
You know, that's very possible! I never thought of that.
According to an article that I read on BBC News, Shellshock affects Mac devices as well. Through this, they can probably access iTunes and iCloud, and thus images on a person's phone.

mind=blown
 

bridgedragon

Diamond
Joined
Nov 24, 2013
Messages
455
Reaction score
269
According to an article that I read on BBC News, Shellshock affects Mac devices as well. Through this, they can probably access iTunes and iCloud, and thus images on a person's phone.

mind=blown
Replying to this on an iPod, I'm so scurred now. I don't want people to hack into my iPod.
 

Qwackey

Platinum
Joined
Feb 8, 2014
Messages
499
Reaction score
251
If people hack my computer, note that I know where you live. My dad works fort Anonym... Nevermind.
 
Joined
Sep 7, 2013
Messages
3,859
Reaction score
1,939
A Random News Site said:
A security flaw discovered in one of the most fundamental interfaces powering the internet has been described by researchers as ‘bigger than Heartbleed', the computer bug that affected nearly every computer user earlier this year.

The 'Bash bug', also known as Shellshock, is located in the command-line shell used in many Linux and Unix operating systems, leaving websites and devices power by these operating systems open to attack.

Like Heartbleed, Shellshock is a pervasive flaw that security researchers say will take years to fix properly. The responsibility to do so however rests with webmasters and systems administrators – rather than average users.

Security firm Rapid7 has rated the bug as 10 out of 10 for its severity, but "low" for complexity - with hackers able to exploit it using just three lines of code.

However, unlike Heartbleed, Shellshock will not require users to rush from site to site changing their passwords but it does give hackers another method of attack that they could potentially use to take over computers or mobile devices.

If Heartbleed's effect on users was akin to unlocking everyone's front door simultaneously, sending people scrambling back home to turn the key (ie change their passwords) then Shellshock is like giving thieves a new type of crowbar to break in to houses with - they're just as likely to use older methods, but it's still a blow for general security.

Security researchers are especially worried about its potential - but as yet unknown - effect on Apple Mac computers, which uses the Bash software which the bug exploits directly in the form of its command-line program Terminal.

Researchers think that Shellshock could be trouble for Mac users.

Robert Graham, a security expert and CEO of Errata Securitytold The Independent: “It's really important that people who maintain websites make sure their computers are patched as quickly as they can. Hackers are already going to all websites and trying out this bug.”

Mr Graham added that as Shellshock affects “a common bit of code that is used all over the place” it will take a long time for experts to fix all affected systems. “Years from now we’ll keep finding yet another device that’s still not been patched,” he said.

The severity of Shellshock has been recognized by even the US government, with the US Department of Homeland Security releasing a warning about the bug and providing patches to fix affected servers.

Despite this, security experts have said that the affect of Shellshock will be minimal. “Of the top 10 ways hackers will hack computers this year, this won't make the list,” said Graham.

The bug itself was first identified by a security team at Red Hat, an American company that provides open-source software and has sponsored initiatives including the Fedora Project and the software for the One Laptop per Child initiative.

It's been estimated that the bug has been present for at least a decade and most likely longer. Writing about the flaw on his blog, security researcher Michal Zalewski commented that it wasn't unusual for Shellshock to have gone unnoticed for so long:

"My take is that it's a very unusual bug in a very obscure feature of a program that researchers don't really look at, precisely because no reasonable person would expect it to fail this way. So, life goes on."

Q&A: The shellshock bug

Q. What is Shellshock?

A. Shellshock is a mistake in the code of a program called Bash, which is typically installed on non-Windows operating systems such as Mac, Unix and Linux. The bug allows hackers to send commands to a computer without having admin status, letting them plant malicious software within systems.

Q. Could it be used to steal my financial details?

A. Yes. If banks or online retailers use older, “mainframe”-style computing systems, they are likely vulnerable. Home routers and modems could also be targeted as a way to get to PCs and laptops.

Q. Are there any indications it has already been exploited?

A. It’s too early to tell. However, authorities fear a deluge of attacks could soon emerge. The US government has rated the security flaw 10 out of 10 for severity.

Q. What can be done to solve it?

A. Security experts around the world are now rushing to find a fix for the bug, but the widespread and varied use of Bash means there won’t be a single solution. Individual organisations and companies such as Apple will develop patches for their own systems.

Q. What can I do to protect against it?

A. Experts recommend not using credit cards or disclosing personal information online for the next few days. Usual precautions are also recommended such as updating anti-virus software and not visiting dodgy websites.
The only way we can protect from it is to not use any credit cards or any personal information online for a few days.
There's nothing it can protect us from it xD
http://www.independent.co.uk/life-s...security-of-millions-of-websites-9754720.html
This is the link for the post.
 

Members online

No members online now.

Forum statistics

Threads
242,192
Messages
2,449,600
Members
523,972
Latest member
Atasci